The General Data Protection Regulation applies to almost every organisation that handles personal data. Compliance is not a one-off project. It is an ongoing discipline that has to be built into your systems, processes and culture.
InfoTech Pro takes you from first assessment to sustained compliance. We review your environment, deliver a prioritised plan and implement the policies, security architecture and controls you need. We then support you after compliance with penetration testing, security operations, policy reviews and a remote CISO.
Our approach
- Discovery and gap analysis: we map the personal data you hold, how it flows and where it is stored, and measure current practice against the regulation.
- Risk assessment and planning: we prioritise gaps by risk and agree a realistic remediation roadmap.
- Policies and governance: we produce information security and data protection policies, processes and procedures, with clear ownership.
- Technical controls: we design and implement the security architecture: access control, encryption, logging, monitoring and secure configuration.
- Incident readiness: we prepare breach detection and response plans so you can meet the 72-hour notification requirement with confidence.
Remote CISO
Not every organisation needs a full-time Chief Information Security Officer, but every organisation needs that accountability. Our remote CISO service gives you a qualified, experienced security leader who owns your information security policies, reports to your board and keeps your programme on track, all at a fraction of the cost of a permanent hire.
Managed security operations (SOC)
We design and run security monitoring that fits your risk profile, either from our own operations centre or embedded with your team on site:
- A 24-hour SOC service, delivered under agreed SLAs and escalation routes by consultants holding CISSP and CEH certifications.
- Design and deployment of SIEM, intrusion detection (IDS and HIDS), file integrity monitoring and vulnerability scanning, connected to your data centres over secure links.
- Regular penetration testing to validate your controls.
- A tailored incident management plan covering investigation, containment, escalation and lessons learned.